CVE-2015-1331
Debian Security Advisory 3317-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
lxclock.c in LXC 1.1.2 and earlier allows local users to create arbitrary files via a symlink attack on /run/lock/lxc/*.
Vulnerabilidad en lxclock.c en LXC 1.1.2 y versiones anteriores, permite a usuarios locales crear archivos arbitrarios a través de un ataque symlink en /run/lock/lxc/*.
Roman Fiedler discovered that LXC had a directory traversal flaw when creating lock files. A local attacker could exploit this flaw to create an arbitrary file as the root user. Roman Fiedler discovered that LXC incorrectly trusted the container's proc filesystem to set up AppArmor profile changes and SELinux domain transitions. A local attacker could exploit this flaw to run programs inside the container that are not confined by AppArmor or SELinux. Various other issues were also addressed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-01-22 CVE Reserved
- 2015-07-22 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2025-06-10 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-59: Improper Link Resolution Before File Access ('Link Following')
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/75999 | Vdb Entry | |
https://github.com/lxc/lxc/commit/72cf81f6a3404e35028567db2c99a90406e9c6e6 | X_refsource_confirm | |
https://service.ait.ac.at/security/2015/LxcSecurityAnalysis.html | X_refsource_misc |
URL | Date | SRC |
---|---|---|
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1470842 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00073.html | 2019-05-31 | |
http://lists.opensuse.org/opensuse-updates/2015-07/msg00066.html | 2019-05-31 | |
http://www.debian.org/security/2015/dsa-3317 | 2019-05-31 | |
http://www.ubuntu.com/usn/USN-2675-1 | 2019-05-31 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linuxcontainers Search vendor "Linuxcontainers" | Lxc Search vendor "Linuxcontainers" for product "Lxc" | <= 1.1.2 Search vendor "Linuxcontainers" for product "Lxc" and version " <= 1.1.2" | - |
Affected
|